There’s a lot to consider when working with FortiGate next-generation firewalls (NGFWs). However, one angle you don’t want to overlook with the hardware is policy routing configurations.
For the short version, this allows your FortiGate NGFWs to direct selected traffic through a preferred WAN connection or IPsec tunnel. Instead of relying on the default routing path, you get more control over your network traffic as a whole. Throughout this article, you’re going to gain a core understanding of policy routing configurations for your Fortinet firewall hardware.
Key Takeaways:
- Use policy routing to direct selected traffic through specific network connections
- Configure a secondary WAN for traffic that needs a preferred path
- Access Policy Routes through System > Feature Visibility
- Send matching DNS traffic toward internal apps through an IPsec tunnel
- Apply policy routing to VoIP, guest networks, high-bandwidth users, internal apps, and more
What is Policy Routing on FortiGate Next-Generation Firewalls?
If you aren’t exactly sure what policy routing does for your Fortinet firewalls, it provides more specific control over where select traffic ends up across your network. Moreover, this goes off the standard routing path where matching traffic can be sent through a designated interface.
Here are several important key details about firewall policy management overall:
- Policy routing gives admins the ability to control the path used by selected network traffic
- Rules can identify traffic based on details like protocol, source IP, or even destination
- Matching traffic follows the path specified by the policy route, instead of the default routing decision
- Note that the SD-WAN can also continue to play a helpful role when the preferred path isn’t available
- Traffic can switch to another available WAN connection if the preferred connection fails
Even though you have a few fallback support pillars here, a matching policy route takes priority. This is why the word ‘configuration’ gets thrown around so much when it comes to network security. Without it, you may not get the best possible experience from your Fortinet FortiGate firewall.
How to Configure Policy Routing for a Secondary WAN
To make sure you end up configuring your FortiGate NGFW properly, there are a couple of steps you’ll want to go through. It’s a lot simpler than you think, but following the right steps is crucial to avoid any unnecessary trial and error.
Step 1: Enable Advanced Routing
Before you dive off into creating a policy route, it’s essential to verify that the routing options you need are available. Moreover, if you find that the option is missing, you may need to enable Advanced Routing.
Here’s how to get that done:
- Navigate to System > Feature Visibility in your FortiGate interface
- Turn on Advanced Routing if Policy Routes is unavailable
- Once you have it enabled, go back to the Network section
- Confirm that Policy Routes is visible before moving on to create the rule
I’d say this is all pretty simple, but once this is out of the way, you’re ready to create a policy route. For the most part, this process is straightforward with Fortinet firewall models.
Step 2: Create a Policy Route
Any time you’re working on creating a policy route, your starting point is determining which device or source traffic should use the secondary WAN. By the end of this, your policy route should specify where that matching traffic should be sent.
Follow the steps below to create a policy route with your FortiGate NGFW:
- Navigate to Network > Policy Routes and create a new policy route
- Set the incoming interface to the LAN interface
- Select the relevant address object and set the destination to all or restrict it as needed
- Select WAN 2 as the outgoing interface, enter its gateway, and save the rule so matching traffic uses WAN 2 instead of WAN 1
Having control of your general network traffic is one thing. On the other hand, they carry a deeper purpose with the likes of internal applications and DNS, for example.
Using Policy Routing for Internal Applications and DNS
This particular scenario would commonly come into play for those dealing with connections from multiple locations. An example of this could include two locations connected through an IPsec tunnel. Whereas the headquarters location hosts internal apps, including DNS, both of which are needed by users in a different location.
Below is how policy routing can help in this situation:
- User DNS queries generally travel toward the internet for resolution
- Internet-based DNS resolution does not provide access to apps hosted within the internal environment
- Turn off DNS encryption so the destination of the traffic can be identified
- Configure DNS using UDP port 53
- Define an address object for the relevant internal domain or server
- Create a rule that matches the internal destination and UDP port 53
- Configure the IPsec tunnel as the policy route’s outgoing interface
From here, matching DNS requests are sent through the IPsec tunnel toward the internal environment, rather than out to the internet. Once again, it might seem complex on paper, but FortiGate next-generation firewalls make it all pretty seamless.
Policy Routing Use Cases for Fortinet Firewalls
Aside from creating a policy route, it also helps to understand the many different use cases behind them. In the table below, you’ll find several popular use cases for policy routing, especially when it comes to business network security.’
| Use Case | How Policy Routing Helps |
|---|---|
| VoIP Traffic | Directs VoIP traffic through a preferred WAN connection |
| High-Bandwidth Users | Routes selected users through a designated network path |
| Guest Networks | Allows guest traffic to use a specific routing path of their own |
| Secondary WAN | Sends matching traffic through WAN 2 instead of the default WAN 1 path |
| Internal Applications | Directs traffic toward internal apps through an IPsec tunnel |
| DNS Traffic | Routes matching DNS requests through the IPsec tunnel toward the internal environment |
I’m sure we can all see a trend here regarding the purpose of policy routing for your Fortinet FortiGate firewall. Regardless of how simple or challenging this may seem, there are many reasons companies like to let the professionals manage these network technicalities.
At the end of the day, policy routing can serve multiple purposes, depending on the type of traffic you’re dealing with. Moreover, the examples highlighted throughout this write-up offer a good look into how policy routing can complement firewall policy management as a whole.
Here’s the Final Word
Policy routing for your FortiGate next-generation firewalls provides more targeted traffic control across your network. Admins can easily and safely keep traffic directed to the right place, giving you better overall control, even when handling multiple locations.
On another note, you can also gain a better understanding of this topic in the video below from one of our dedicated network engineers at Firewalls.com. You can also hop into a chat with us and learn everything you need to know about policy routing with Fortinet firewall models.
Frequently Asked Questions
What is Policy Routing on a FortiGate Firewall?
Policy routing directs selected traffic through a specific path based on conditions such as source IP, destination, incoming interface, or protocol.
How Can I Configure a FortiGate to Use a Secondary WAN?
Enable Advanced Routing, open Network > Policy Routes, identify the desired source traffic, and set WAN 2 and its gateway as the outgoing path.
Can FortiGate Policy Routing Work with SD-WAN?
Yes, a matching policy route takes priority, while SD-WAN can still provide an alternative path when the preferred connection is unavailable.
Can Policy Routing Direct DNS Traffic Through an IPsec Tunnel?
Yes, the example in this article uses a policy route matching an internal destination and UDP port 53, with the IPsec tunnel selected as the outgoing interface.
What Types of Traffic Can Benefit from FortiGate Policy Routing?
Common examples include VoIP traffic, high-bandwidth users, guest networks, secondary-WAN traffic, internal apps, and DNS traffic.


